Written and maintained by CASRAI Editorial Board
Last updated
Verified against ISED’s own (now-archived) AIDA companion document, the Parliament of Canada’s official LEGISinfo record for Bill C-27, and Wikipedia’s account of the 44th and 45th Canadian Parliaments; last checked September 2026. No organization was ever required to comply with the Artificial Intelligence and Data Act, because it never became law. The bill that would have created it — Bill C-27, the Digital Charter Implementation Act, 2022 — stalled in a House of Commons committee for the better part of two years and died when Parliament was prorogued on January 6, 2025. This is a postmortem: what AIDA would have required of Canadian labs and deployers had it passed, and the specific, verifiable sequence of events that meant it didn’t.
What Bill C-27 Was, and Where AIDA Sat Inside It
Bill C-27 had its first reading in the House of Commons on June 16, 2022. It bundled together three separate pieces of legislation: the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act, and, as its third and most novel part, the Artificial Intelligence and Data Act. AIDA was the government’s first attempt at a horizontal, cross-sectoral AI law for Canada — not a sector-specific rule for hiring or lending, but a general framework meant to apply wherever an AI system crossed a defined impact threshold. In November 2022, ISED published a detailed companion document laying out how AIDA would actually work in practice; that document is now itself archived, carrying the Government of Canada’s standard notice that it “has not been altered or updated since it was archived.”
What Counted as a “High-Impact” AI System
AIDA’s obligations were not going to apply to every AI system — only to ones the companion document classified as “high-impact.” The document’s own examples fell into four categories:
- Screening systems that decide, recommend, or predict outcomes affecting access to services or employment — credit decisions and hiring being the document’s own examples.
- Biometric systems that use biometric data to identify a person remotely or to predict their characteristics, psychology, or behaviour.
- Content recommendation systems, flagged specifically for their demonstrated ability “to influence human behavior, expression, and emotion on a large scale.”
- Health and safety-critical systems, with autonomous driving and clinical triage decision systems named as the document’s own examples.
Obligations by Lifecycle Stage
Rather than a single, static compliance checklist, AIDA’s companion document structured obligations around four stages of a high-impact system’s life:
- Design: an initial risk assessment, evaluation of potential dataset bias, and a determination of how interpretable the system needed to be — all before development began.
- Development: documentation of the datasets and models used, evaluation and validation of the system, built-in human oversight mechanisms, and a record of intended use cases and known limitations.
- Making available for use: maintaining that design-and-development documentation, giving downstream users information about the datasets and constraints involved, and assessing deployment-specific risk.
- Managing operations: logging system outputs, maintaining human oversight in live operation, and intervening based on defined operational parameters.
A business responsible for a regulated activity involving a high-impact system would also have had to notify the Minister of Innovation, Science and Industry if the system caused, or was likely to cause, “material harm” — the companion document commits to the notification duty itself but leaves the specific deadline and procedural detail to future regulations that, because AIDA never passed, were never written.
The AI and Data Commissioner
AIDA proposed a new statutory role, an AI and Data Commissioner, appointed to support the Minister rather than to sit as an independent regulator in their own right. Its early mandate would have leaned toward education and compliance assistance — helping businesses understand and meet their obligations — with enforcement powers meant to “gradually evolve” as the regulatory ecosystem matured. The role was also designed to coordinate across other regulators with a stake in AI and to study systemic AI impacts more broadly, rather than to function purely as an enforcement office from day one.
Three Separate Penalty Tracks
Where AIDA broke most clearly from a single-penalty model was in enforcement, which the companion document splits into three distinct tracks with different burdens of proof and different bodies behind them:
- Administrative monetary penalties (AMPs): described as a flexible compliance tool, contingent on future regulations and intended to apply once businesses had had an adjustment period to come into compliance.
- Regulatory offences: reserved for more serious non-compliance, prosecuted by the Public Prosecution Service of Canada, requiring guilt to be proven beyond a reasonable doubt, with a due-diligence defence available to a business that could show it took reasonable care.
- Criminal offences: three specific prohibitions aimed at knowing or reckless harmful conduct — unlawful use of data, knowingly deploying a harmful system, and fraudulent AI deployment.
Why It Died
AIDA’s committee stage is where the bill actually stopped moving. Second reading and referral to the House of Commons Standing Committee on Industry and Technology happened on April 24, 2023. From there, per Parliament’s own LEGISinfo record, the bill remained “at consideration in committee” through all of 2024 — report stage, third reading, and every Senate stage are marked “not reached.” It was still sitting in committee, unresolved, when Prime Minister Justin Trudeau announced on January 6, 2025 that he would resign once a successor was chosen, and advised the Governor General to prorogue Parliament until March 24, 2025.
Prorogation ends a parliamentary session, and any bill that has not received royal assent by that point does not carry over automatically — it would need the new session’s House to agree to reinstate it at the stage it left off. That chance never arrived. Mark Carney, having become prime minister, requested and received dissolution of Parliament on March 23, 2025 — one day before the House was even scheduled to resume sitting — to call a federal election for April 28, 2025. The House of Commons never sat again between the prorogation and the dissolution, so no reinstatement vote on Bill C-27 was ever possible. The 45th Parliament was seated on May 26, 2025, and as of this writing no successor to AIDA or to Bill C-27 has been introduced in it. Bill C-27 never passed; Canada currently has no comprehensive federal AI law in force or in progress.
A Contrast Worth Noting: A Comprehensive AI Law That Did Pass in the Same Window
AIDA’s stall is more legible next to a comprehensive AI law that crossed the finish line on roughly the same timeline. South Korea’s own comprehensive AI framework law took effect in January 2026, reported at the time as the first law of its kind to take effect anywhere — the same broad category of horizontal, cross-sectoral AI legislation AIDA was designed to be, working through the same run-up years, arriving at the opposite outcome. AIDA’s committee stall and Korea’s enactment are not directly comparable in their substance — CASRAI has not verified Korea’s specific requirements closely enough to draw that comparison here — but the contrast in outcome, on the same basic type of bill over the same few years, is itself the useful data point.
CASRAI’s Own NIKOLAI: What AIDA Would Have Made Trackable, and Why There’s No Crosswalk Row
Because AIDA never took effect, no organization was ever required to make a disclosure under it, and none can be. That makes it a clean, negative example for NIKOLAI, CASRAI’s own independent, unendorsed dictionary of frontier-AI-safety elements: a framework whose structure would have generated real, NIKOLAI-trackable obligations, but that never got the chance to.
Two parallels are concrete enough to name directly. AIDA’s material-harm notification duty — a business notifying the Minister when its high-impact system caused or was likely to cause material harm — sits in the same conceptual space as NIKOLAI’s Incidents track (N7), specifically its Incident reporting deadline and recipient element, which is where NIKOLAI documents who a real framework requires notice to go to and on what schedule. AIDA’s own companion document never got to specify that schedule; the regulations that would have set it were never written. Separately, AIDA’s lifecycle-stage obligations implicitly assumed some accountable party inside a business signing off on design-stage risk assessments and deployment decisions — the same role NIKOLAI’s Accountable Decision-Maker and Sign-Off element (Track N9) catalogs for frameworks that did pass.
That second element is a useful contrast precisely because it does carry real crosswalk rows today: it maps how California SB 53 and the EU AI Act’s GPAI Code of Practice, among other enacted frameworks, actually assign approval authority — rows built because those frameworks exist, in force, with text NIKOLAI can read. NIKOLAI has no equivalent row for AIDA, and none should be implied by this guide. Every NIKOLAI crosswalk row is a shadow mapping unless an organization has explicitly filed a Mapping Declaration confirming it, and no organization has ever filed one for a Canadian AI law, because there has never been a Canadian AI law in force to file one against. This piece draws a structural “what if” comparison between AIDA’s design and NIKOLAI’s existing elements; it is not, and should not be read as, a NIKOLAI crosswalk mapping for Canada.
FAQ
Did AIDA ever become law?
No. AIDA was the third part of Bill C-27, which stalled in House of Commons committee through 2024 and died when Parliament was prorogued on January 6, 2025, before it could reach report stage, third reading, or the Senate.
What would AIDA have regulated?
“High-impact” AI systems, per ISED’s companion document: systems used in screening for services or employment, biometric identification or prediction, content recommendation, and health or safety-critical applications such as autonomous driving or clinical triage.
What penalties would AIDA have created?
Three separate tracks: administrative monetary penalties set by future regulation, regulatory offences prosecuted by the Public Prosecution Service of Canada with a due-diligence defence, and three specific criminal offences for knowing or reckless harmful conduct.
Is there a replacement bill for AIDA?
Not as of this writing. The 45th Parliament, seated May 26, 2025 after the April 28, 2025 general election, has not introduced a successor to Bill C-27 or a comprehensive federal AI bill.
Does NIKOLAI have a crosswalk row for AIDA or Canada?
No, and none is implied by this guide. NIKOLAI, CASRAI’s own independent and unendorsed dictionary of frontier-AI-safety elements, only carries crosswalk rows for frameworks an organization has filed a Mapping Declaration against, and no Canadian AI law has ever been in force to file one against. The comparisons here are CASRAI’s own structural analysis, not a NIKOLAI mapping.







